Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Hatchet cross-tenant data exposure via missing authorization (CVE-2026-42572)

A missing authorization directive on Hatchet's GET /api/v1/stable/dags/tasks endpoint skipped the tenant-membership check, letting any authenticated user on the instance retrieve task metadata for DAGs belonging to other tenants. The issue is fixed in version 0.83.39.

Disclosed 14 May 2026 · Record updated 13 September 2026

Impact

Users authenticated to any tenant could query another tenant's DAG UUID and receive that tenant's task metadata, enabling cross-tenant information disclosure.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-42572